About PAM Best Practice
Privileged access management, taught as a discipline and built from real delivery.

Our aim
Our aim is to see privileged access management taught as a discipline in its own right: in colleges, in universities and across industry.
Privileged accounts reach an organisation’s most critical systems, sensitive data and infrastructure. Yet most people only learn how that access should be controlled once they are already in a role that depends on it.
We want students to leave college and university with a working understanding of how privileged access is governed and controlled, and we want teams already in industry to share that same understanding, whatever tools they use.
PAM Best Practice is an independent, vendor-neutral education provider. We turn hands-on PAM delivery experience into a structured curriculum that colleges, universities and organisations can teach, and that practitioners, teams and students can learn from and apply.

Built from delivery, not from a textbook
Everything we teach is drawn from large-scale enterprise PAM implementations across infrastructure, cloud, applications and operational technology: the programmes that delivered, the ones that stalled, and what made the difference.
That is why our guides concentrate on the work that decides whether a programme succeeds. Who owns access decisions. How discovery is really done. How processes, controls and adoption are sequenced. How evidence is produced for an auditor.
The modules turn those lessons into practical exercises, and the ten failure modes that stall PAM projects are each paired with the discipline that prevents them.
This is not just theory. It is what implementation teams learn the hard way.

Ten modules, ten practitioners
The PAM Academy follows one organisation, Abby Steel, from a privileged access breach to a mature programme. Each of the ten modules is told by a different practitioner facing a real problem.
Ahmed, the infrastructure engineer, starts with PAM Foundations. Layla builds the strategy and operating model, Priya runs discovery, Omar secures access by risk, Sofia evaluates platforms, Grace leads the rollout, Amara takes on monitoring and incident response, Kenji looks to the future, Elena audits the whole programme, and Marta, a CISO at another company, learns why her projects failed.
Telling the course through people makes it easier to see how privileged access affects every part of an organisation, from the service desk to the board.
Modules 1 to 5 are available now, and modules 6 to 10 are coming soon. Module 1 is free. See the full learning roadmap.

The Periodic Table of PAM Security
At the heart of the curriculum is the Periodic Table of PAM Security: 112 elements in seven categories that map everything a PAM programme has to address. Every module teaches part of the table.
Explore the Periodic Table or browse the guides in the Knowledge Hub.

A free self-assessment, built from the course
Each module ends with a practical exercise. We have compiled all ten into one free self-assessment that scores a PAM programme against the whole Periodic Table.

Why PAM deserves a place in education and industry
PAM is not simply another security technology. Privileged access is one of the most common routes attackers use to reach the systems organisations depend on. Verizon found credential abuse was the initial access vector in 22% of breaches in its 2025 Data Breach Investigations Report.
The skills to manage it are scarce. The Department for Science, Innovation and Technology reports that 57% of UK businesses now have a basic technical cyber skills gap, up from 49% a year earlier, in Cyber security skills in the UK labour market 2026. The World Economic Forum lists identity and access management specialists among the most acute cyber skills shortages in its Global Cybersecurity Outlook 2026.
And PAM affects everyone: end users, security teams, IT and database teams, developers, and the business leaders who approve access and carry the risk.
PAM sits at the intersection of people, process and technology. That is why it needs to be taught as a discipline.

Vendor-neutral by design
PAM Best Practice is independent. It is not owned or funded by any PAM vendor, and no vendor produces or reviews our content.
We teach the discipline that any tool sits inside. We do not name, rank or compare products, we take no referral or reseller fees from vendors, and we do not give product selection advice. Tools are taught as capabilities, whichever product provides them.
Our material is designed to complement vendor training, not replace it.
If you spot something that reads as favouring a product, tell us at enquiries@pambestpractice.co.uk and we will correct it.

For educators
PAM Best Practice began as guest lectures at Teesside University. The curriculum is designed to sit inside cyber security, computing and business courses, adding the specialist application of privileged access to the foundations students already have.
A cyber security degree gives the broad foundation. Identity and access management covers who should have access. PAM Best Practice covers how organisations control, govern and operate their highest-risk access.
The ten modules, the Periodic Table and the module exercises give students applied practice on a real or case-study organisation. They complement existing modules rather than replace them, and institutions can teach and assess the material inside courses they already run.
What institutions receive: access to the ten modules for each cohort, the module exercises for applied coursework and assessment, the Periodic Table as a competency framework to map against your learning outcomes, and support to fit the material into a course you already run.
Deliberately out of scope: programming, packet analysis, cryptographic mathematics and malware reverse engineering.

For industry teams
Vendor training teaches people to operate a product. Our material covers what sits around it: strategy, ownership, discovery, process design, risk-based controls, deployment, monitoring and continuous improvement.
Teams use the modules to build a shared understanding across security, IT operations, delivery, GRC and leadership, and the free self-assessment to see where their programme really stands.
Bring PAM into your course or your team
A few questions we get
Where does the content come from?
From practitioners who have designed, deployed and run PAM programmes. The modules use a composite organisation, Abby Steel, so the lessons are realistic without describing any real client.
Is PAM Best Practice linked to a PAM vendor?
No. We are independent of every vendor. Our content does not recommend products, and no vendor produces or reviews it.
Is the course accredited?
Not yet. We are working with universities and colleges towards accreditation. In the meantime, institutions can teach and assess the material inside courses they already run.
Does this replace existing cyber security modules?
No. It builds on the foundations students already have and adds the specialist application of privileged access.
What is the Periodic Table of PAM Security?
A framework of 112 elements in seven categories that maps everything a PAM programme has to address, from threat actors to success enablers.
Is the self-assessment really free?
Yes. It brings together the exercise at the end of each module into one toolkit. You do not need the course to use it, although the modules give the context behind every question.
Who is the curriculum for?
Cyber security, computing and business students and educators, and practitioners who want a discipline-level understanding of PAM rather than training on a single product.
Sources: Verizon 2025 DBIR; DSIT, Cyber security skills in the UK labour market 2026; World Economic Forum, Global Cybersecurity Outlook 2026.
